全部标签
目录标签

#sarif

公开记录中带有此标签的全部仓库——标签来自其 GitHub 主题或软件包注册表发布的关键词。健康度量遵循与记录其余部分相同的版本化方法论。

47 条记录
标签为“sarif”按健康指数排序
PyPI · npm
94卓越健康指数
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/月2026年7月16日
Apache-2.02026年7月16日 · 指标 2.10.0
PyPI · npm
94卓越健康指数
sattyamjjain/agent-audit-kit
Static scanner for MCP-connected AI agent pipelines — 271 rules across 12 categories, 12 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.
Python★ 13↓ 2,808/月2026年8月2日
MIT2026年8月2日 · 指标 2.10.0
npm
91优秀健康指数
Siteimprove/alfa
:wheelchair: Suite of open and standards-based tools for performing reliable accessibility conformance testing at scale
HTML · TypeScript★ 130↓ 96.3K/月2026年7月31日
MIT2026年7月31日 · 指标 2.10.0
PyPI
87优秀健康指数
Cranot/roam-code
Local codebase intelligence CLI + MCP server for AI coding agents: SQLite code graph, 28 languages, 238 commands, 224 MCP tools, change-safety gates, audit evidence, zero API keys.
Python★ 498↓ 5,430/月2026年7月15日
Apache-2.02026年7月15日 · 指标 2.10.0
Go
86优秀健康指数
Nox-HQ/nox
Open-source security scanner with first-class AI app security (prompt injection, embedding leakage, agent over-privilege, MCP hardening). Polyglot AIBOM, SARIF, SBOM. Cosign-signed plugin marketplace. Offline-first, agent-native via MCP.
Go★ 02026年7月24日
Apache-2.02026年7月24日 · 指标 2.10.0
Go · PyPI
86优秀健康指数
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 92026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
npm
86优秀健康指数
microsoft/axe-sarif-converter
An axe-core reporter that outputs axe scan results in SARIF format (http://sarifweb.azurewebsites.net/)
TypeScript★ 38↓ 76.1K/月2026年7月21日
MIT2026年7月21日 · 指标 2.10.0
npm
86优秀健康指数
ofri-peretz/eslint
Security & code-quality ESLint plugins — 350+ CWE-mapped rules across 18 domains, ESLint + Oxlint. The lint layer AI-generated code needs.
TypeScript · MDX★ 12↓ 77.5K/月2026年7月25日
MIT2026年7月25日 · 指标 2.10.0
npm · PyPI
84优秀健康指数
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 7,189/月2026年8月22日
AGPL-3.02026年8月22日 · 指标 2.10.0
PyPI
84优秀健康指数
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 502026年8月22日
自定义许可证2026年8月22日 · 指标 2.10.0
Go
81优秀健康指数
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 82026年7月23日
Apache-2.02026年7月23日 · 指标 2.10.0
npm · crates.io
78良好健康指数
0sec-labs/foxguard
A fast universal code security scanner, written in Rust. Batteries included: supports 12 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Rust★ 277↓ 6,899/月2026年7月17日
MIT2026年7月17日 · 指标 2.10.0
npm
78良好健康指数
Null-Square/Null-CLi
Open-source AI pentest and compliance-readiness CLI by NullSquare.
TypeScript · JavaScript★ 81↓ 147/月2026年8月4日
自定义许可证2026年8月4日 · 指标 2.10.0
PyPI
78良好健康指数
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/月2026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
PyPI
78良好健康指数
justinchuby/lintrunner-adapters
Adapters and tools for lintrunner
Python★ 6↓ 940.1K/月2026年7月21日
自定义许可证2026年7月21日 · 指标 2.10.0
Go
77良好健康指数
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 02026年7月19日
Apache-2.02026年7月19日 · 指标 2.10.0
npm · PyPI
77良好健康指数
raccioly/docguard
The enforcement tool for Canonical-Driven Development (CDD). Audit, generate, and guard your project documentation. Zero dependencies.
JavaScript★ 21↓ 5,005/月2026年7月21日
MIT2026年7月21日 · 指标 2.10.0
npm · Go
73良好健康指数
HodeTech/Leakwatch
High-performance open-source secret scanner — detect, verify & report leaked API keys, tokens & credentials in code, Git history, container images, and the cloud.
Go★ 2↓ 46/月2026年7月27日
MIT2026年7月27日 · 指标 2.10.0
npm · PyPI
73良好健康指数
oaslananka/boardreadyops
End-to-end hardware release pipeline for KiCad: generate, validate, sign, and package manufacturer-ready releases as a CLI and GitHub Action.
TypeScript★ 3↓ 3,738/月2026年7月17日
MIT2026年7月17日 · 指标 2.10.0
npm
73良好健康指数
stainless-code/codemap
Cut AI-agent token waste ~90% — query a local SQLite structural index of your JS/TS/CSS codebase with SQL in one round-trip instead of 3–5 file reads. Symbols, imports, calls, components, CSS tokens, coverage, markers. CLI, MCP (21 tools), HTTP, GitHub Action, ESM API. 71 recipes; AST+resolver; SARIF/audit/baselines for CI.
TypeScript★ 8↓ 8,315/月2026年7月26日
MIT2026年7月26日 · 指标 2.10.0
Go
71良好健康指数
Vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Go · Open Policy Agent★ 252026年9月5日
自定义许可证2026年9月5日 · 指标 2.10.0
npm
71良好健康指数
YawLabs/ctxlint
Lint your AI agent context files (CLAUDE.md, AGENTS.md, etc.) against your actual codebase
TypeScript★ 7↓ 21.4K/月2026年8月6日
MIT2026年8月6日 · 指标 2.10.0
npm
69良好健康指数
goklab/guardvibe
Security infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6,125/月2026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
PyPI
67良好健康指数
raccioly/websec-validator
Local-first security recon that briefs your AI coding agent: facts + tailored probes, code-in / artifacts-out. No LLM, no server, no running app.
Python★ 22026年7月31日
MIT2026年7月31日 · 指标 2.10.0
Go
67良好健康指数
tiagosilva07/zyrax-guard
Audit your AI agent configs before you run them — prompt injection, rogue MCP servers, credential-exfil. Plus dependency vetting.
Go★ 22026年8月28日
MIT2026年8月28日 · 指标 2.10.0
Packagist · npm
65良好健康指数
blundergoat/gruff-php
Opinionated PHP code-quality analyzer that scores findings across quality pillars and emits reports for terminals, CI, SARIF, HTML, and a local dashboard.
PHP★ 1↓ 8,483/月2026年7月16日
MIT2026年7月16日 · 指标 2.10.0
Go · npm
62中等健康指数
LarsArtmann/art-dupl
Professional code clone detection for Go. AST-based structural + semantic detection with suffix tree algorithms, 3 matching modes, 7 output formats, templ support, and CI baseline gating.
Go★ 22026年8月31日
自定义许可证2026年8月31日 · 指标 2.10.0
Go
62中等健康指数
git-pkgs/sarif
Go library for reading, writing, and validating SARIF 2.1.0 logs
Go★ 12026年7月15日
MIT2026年7月15日 · 指标 2.10.0
Go
62中等健康指数
icearp/disco-cli
Discover, map & secure AWS, Azure, & GCP. Scan resources and their relationships into a local inventory, visualize the graph, and run OPA policy checks with SARIF output.
Go★ 12026年8月30日
MIT2026年8月30日 · 指标 2.10.0
Go
62中等健康指数
kanywst/brtc
Cost calculator for offline password brute-force attacks: time + USD per GPU profile, with a CI gatekeeper.
Go★ 02026年7月26日
MIT2026年7月26日 · 指标 2.10.0